Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Zyxel and Veeam Vulnerabilities Under Active Exploit

Zyxel and Veeam Vulnerabilities Under Active Exploit

Posted on September 22, 2026 By CWS

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently added a significant vulnerability affecting Zyxel GS1900 series switches to its Known Exploited Vulnerabilities (KEV) catalog. This decision follows evidence that the flaw, although now patched, is being actively exploited. Identified as CVE-2026-7273 with a CVSS score of 8.8, the issue involves a stack-based buffer overflow that permits arbitrary operating system command execution.

Zyxel Vulnerability Details

The Zyxel GS1900 series switches are susceptible to a stack-based buffer overflow vulnerability within their CGI program. This flaw allows unauthenticated attackers on the LAN to potentially execute operating system commands through a specially crafted HTTP request. Zyxel addressed this issue by releasing patches for various models in June 2026.

The affected switch firmware versions and their respective fixes include GS1900-8, GS1900-8HP, GS1900-10HP, GS1900-16, GS1900-24, GS1900-24E, GS1900-24EP, GS1900-24HPv2, GS1900-48, and GS1900-48HPv2. Despite these updates, CISA has not disclosed specifics regarding the entities behind the exploitation, the timeline of the attacks, or the success rate of these malicious efforts.

Security Measures and Acknowledgements

In response to the ongoing exploitation, Federal Civilian Executive Branch (FCEB) agencies have been mandated to implement the necessary patches by September 24, 2026. Zyxel credited the discovery and reporting of the vulnerability to Lei Gu, Jun Cao, Zhiqing Rui, Jingzheng Wu, and Tianyue Luo from ISCAS. However, Zyxel’s official advisory has yet to confirm the active exploitation status.

Veeam Agent for Windows Exploitation

Simultaneously, Arctic Wolf has flagged an active exploitation of CVE-2026-32996, a local privilege escalation vulnerability in Veeam Agent for Microsoft Windows. This flaw, rated with a CVSS score of 7.3, enables attackers with local access to gain SYSTEM-level control over affected endpoints.

The vulnerability originates from the Veeam Endpoint Backup service’s mishandling of elevated client sessions via the local gRPC named pipe. This issue allows attackers to retrieve and exploit session UIDs logged in a location accessible to standard users, enabling them to execute commands with elevated privileges. A public proof of concept on GitHub demonstrates this exploit by running the ‘whoami’ command and logging the output.

Both the Zyxel and Veeam vulnerabilities highlight the critical need for prompt patching and vigilant network monitoring to safeguard against potential exploitation. Organizations are encouraged to stay updated with security advisories and patches to protect their systems from these threats.

The Hacker News Tags:buffer overflow, CISA, CVE-2026-32996, CVE-2026-7273, Cybersecurity, endpoint security, Exploitation, local privilege escalation, network security, SYSTEM access, Veeam, Vulnerabilities, Zyxel

Post navigation

Previous Post: Japan Dismantles North Korean Laptop Farm Amid Global Cyber Scheme
Next Post: WordPress Addresses Critical Security Flaw ‘Click2Shell’

Related Posts

SysAid Flaws Under Active Attack Enable Remote File Access and SSRF SysAid Flaws Under Active Attack Enable Remote File Access and SSRF The Hacker News
Elementor Pro Flaw Allows Remote Code Execution Risk Elementor Pro Flaw Allows Remote Code Execution Risk The Hacker News
Two Distinct Botnets Exploit Wazuh Server Vulnerability to Launch Mirai-Based Attacks Two Distinct Botnets Exploit Wazuh Server Vulnerability to Launch Mirai-Based Attacks The Hacker News
Why Exposed Credentials Remain Unfixed—and How to Change That Why Exposed Credentials Remain Unfixed—and How to Change That The Hacker News
New Linux Zapscape Vulnerability Threatens KVM Hosts New Linux Zapscape Vulnerability Threatens KVM Hosts The Hacker News
WebRTC Skimmer Evades CSP to Steal E-Commerce Data WebRTC Skimmer Evades CSP to Steal E-Commerce Data The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Vulnerability Found in D-Link Router
  • Malicious npm Package Conceals Code in Runtime
  • Windows Vulnerability Exploited Through Malicious DLLs
  • WordPress Addresses Critical Security Flaw ‘Click2Shell’
  • Zyxel and Veeam Vulnerabilities Under Active Exploit

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Vulnerability Found in D-Link Router
  • Malicious npm Package Conceals Code in Runtime
  • Windows Vulnerability Exploited Through Malicious DLLs
  • WordPress Addresses Critical Security Flaw ‘Click2Shell’
  • Zyxel and Veeam Vulnerabilities Under Active Exploit

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark